Splunk® App for Infrastructure

Use Splunk App for Infrastructure

Download manual as PDF

This documentation does not apply to the most recent version of InfraApp. Click here for the latest version.
Download topic as PDF

About Splunk App for Infrastructure

Splunk App for Infrastructure is a tool that provides insight into the performance of Linux servers, Microsoft Windows servers, and Amazon EC2, ELB and EBS instances. Splunk App for Infrastructure utilizes metrics for performance monitoring, and log data for deep understanding and troubleshooting of your server infrastructure.

For a video overview of Splunk App for Infrastructure, see Video: Introducing Splunk App for Infrastructure.

Core Features

Splunk App for Infrastructure provides everything you need for deploying metrics and log data collection, entity discovery, server monitoring, and performance analysis and troubleshooting. The Insight has the following primary sections.

  • The Add Data view gets you started with data collection. From this view you can set up data collection on Linux, Windows, and Mac OS X servers for both system metrics and logs. You can also create accounts for polling critical performance metrics for your Amazon EC2, ELB and EBS entities. For more information, see How to add data to Splunk App for Infrastructure.
  • The Investigate views allow you to browse a list of discovered entities, create groups of entities using entity metadata, view the Entity Overview to monitor the health of an entity, link to Group and Entity Analysis Workspaces for deeper insight, and view all of your server entities as tiles in the Infrastructure Overview. You can also filter for specific entities or groups that triggered alerts according to specific dimensions. For more information, see Investigate Your Infrastructure.
  • The Alerts view displays triggered alert conditions. From this view you can drill down into the Analysis Workspace from the Entity or Group views to perform root cause analyses on a particular alert for an entity or group. You can also filter for specific entities or groups that triggered alerts according to specific dimensions. For more information, see View and Manage Alerts.

Investigate Your Infrastructure

Use the Investigate views, including the Infrastructure Overview, List View, and Analysis Workspace to monitor your infrastructure.

Investigate the Infrastructure Overview

Monitor the health of your system using the Infrastructure Overview. This view is used to quickly understand availability and performance of your server infrastructure. You can choose a specific performance metric and set a threshold to better understand your high and low performing systems. From this view you can access quick information including hostname and IP address, as well as drill down into the Analysis Workspace for a specific server where you can continue to analyze and understand server performance. For more information, see Using the Infrastructure Overview in Splunk App for Infrastructure.

Investigate the List View

Use the List View to view your entities or groups, their status as active or inactive, and sort them by dimensions. You can also drilldown into the Analysis Workspace of an entity or group being monitored to review details or troubleshoot an issue. For more information, see Using the List View in Splunk App for Infrastructure.

Investigate the Entity Overview

Use the Entity Overview to view performance charts that give a quick view of the performance of entities. From this overview, get a summary of metrics being used by the entity, such as CPU, network, memory, disk, system information, dimensions and more. For more information, see Using the Entity Overview in Splunk App for Infrastructure.

Investigate the Analysis Workspace

Use the Analysis Workspace to analyze performance metrics for a single entity or a group of entities. Determine poor performing entities by metrics, or determine a point in time when multiple entities began performing in a similar way. Create alert conditions and search logs collected from your servers to perform root cause analysis and understand why your infrastructure is performing the way it is. View and search for entities in a group, or view all groups an entity is a part of for easy navigation. For more information, see Using the Analysis Workspace in Splunk App for Infrastructure.

View and Manage Alerts

Admin privileges are required to create and manage alerts.

Use alerts to monitor triggered events and perform root cause analyses. The Alerts page displays a list of triggered alerts. Select the Entities or Groups view and filter alerts by dimensions or group names. When you select a triggered alert, you can drill down into the Analysis Workspace, where you can continue to investigate performance issues during the time of the alert for the entity or group, and modify or delete the alert condition or threshold. For more information about alerts for entities and groups, see Monitor and investigate alerts in Splunk App for Infrastructure.

  NEXT
Get started using Splunk App for Infrastructure

This documentation applies to the following versions of Splunk® App for Infrastructure: 1.3.0, 1.3.1


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters